Re: RE: [PHP] Re: php security books

2007-07-04 Thread Andrew Hutchings
In article <[EMAIL PROTECTED]>quickshifti [EMAIL PROTECTED] ("Nathan Nobbe") wrote: > [EMAIL PROTECTED] > Content-Type: text/plain; charsetãO-8859-1; > format\owedContent-Transfer-Encoding: quoted-printable > Content-Disposition: inline > > the root user issue aside, i still dedicate a separa

Re: RE: [PHP] Re: php security books

2007-07-04 Thread Andrew Hutchings
In article <[EMAIL PROTECTED]>[EMAIL PROTECTED] ("bruce") wrote: > andrew... > > are you sure about this... i would have thought that if you have an > apache user 'apache' and allow php to be run as/by 'apache' than this > would providecomplete access to anything php needs to do as 'apache'.

Re: RE: [PHP] Re: php security books

2007-07-04 Thread Nathan Nobbe
the root user issue aside, i still dedicate a separate file in /var/log for my php apps. -nathan On 7/4/07, Andrew Hutchings <[EMAIL PROTECTED]> wrote: In article <[EMAIL PROTECTED]>[EMAIL PROTECTED] ("bruce") wrote: > andrew... ¾ > are you sure about this... i would have thought that if yo